Risk and Compliance Officer, Central Tech

Booking Booking · Hospitality · Amsterdam, Netherlands · Security & Infrastructure

This role partners with risk owners in the Data & Machine Learning Platform domain and development teams to identify risks, drive risk responses, and support the design of internal controls. It focuses on ensuring regulatory compliance (SOX, NIST, DMA, DSA, EU Act Act, NIS2), architecting guardrails for secure onboarding, and driving automation initiatives for compliance bottlenecks. The role requires experience with scripting languages like Python and GRC tools, and a strong understanding of technology risk domains including AI/GenAI.

What you'd actually do

  1. Act as a Risk Partner to platform owners from the Data & Machine Learning Platform domain and development teams, providing expertise in SOX, NIST, DMA, DSA, EU Act Act, NIS2 and security best practices and tailoring compliance requirements to cloud and devops environments
  2. Architect "Guardrails" for secure and compliant onboarding to cloud environments, ensuring that security is "baked in" rather than "bolted on."
  3. Drive Automation Initiatives by identifying manual compliance bottlenecks and designing efficient workflows leveraging automation and Al.
  4. Execute Technical Risk Assessments for new platforms and major architectural changes. You will identify risks in modern tech stacks and support teams in implementing appropriate safeguards.
  5. Deliver Data-Driven Risk Insights by reporting on risk coverage and issues using tools like Jira and ServiceNow.

Skills

Required

  • Risk management principles
  • Automating complex processes
  • SOX
  • NIST
  • DMA
  • DSA
  • EU Act Act
  • NIS2
  • Python
  • GRC tool administration
  • Technology Risk domains (IT, Cybersecurity, Data Security, AI/GenAI, Fraud, Trust & Safety)
  • Internal control requirements and design

Nice to have

  • large e-commerce or tech companies experience
  • first-line of defence experience

What the JD emphasized

  • automate complex processes
  • hands-on experience in automating workflows and processes
  • The ability to identify opportunities for automation, design efficient workflows, and implement robust, scalable solutions is critical for this role.